ZeroHour

CVE-2025-23359

PoC
CVSS 3.1
8.1 high
EPSS
4%p89
Published
()
Modified
Description

NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

Vendors
nvidia
Products
nvidia container toolkit, nvidia gpu operator
Weakness
CWE-367
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news